Launching managed CRA Article 14 reporting for open source maintainers
The EU's Cyber Resilience Act (CRA) now requires open-source software maintainers to report active security exploits and major incidents to the EU. Starting September 11, 2026, this law applies to all open-source projects, even those released before the deadline.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Not confirmed
- Exploited
- Not confirmedNo confirmation recorded
What to do
If you maintain or steward an open-source project available in the EU, check if your project has faced active exploitation or a severe security incident since September 11, 2026. If so, you must report it to the EU's designated platform under Article 14 of the Cyber Resilience Act.
Visit the EU Cyber Resilience Act reporting platform to submit active exploit reports or severe incident details. Follow the platform's instructions to ensure compliance with EU requirements. If unsure, consult the official CRA guidance for open-source maintainers.
Technical details
The European Cyber Resilience Act (CRA) Article 14, effective September 11, 2026, imposes reporting obligations on open-source stewards, maintainers of fully open-source projects (FOSS) with no commercial revenue, who manage software available in the EU. Under this law, stewards must report active exploits and severe security incidents to national cybersecurity authorities and ENISA via a unified EU platform within strict deadlines: an initial warning within 24 hours, a full notification by 72 hours, and a final report later. Affected users must also be notified of risks and mitigation steps.
Unlike commercial manufacturers, open-source stewards face no financial penalties but remain legally bound to comply with transparency and incident disclosure requirements. The law applies retroactively to all software previously distributed in the EU, regardless of release date.